supercollider
supercollider copied to clipboard
[Snyk] Fix for 4 vulnerabilities
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-ANSIREGEX-1583908 |
Yes | Proof of Concept | |
| 811/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 9.8 |
Arbitrary Code Execution SNYK-JS-FRONTMATTER-569103 |
Yes | Proof of Concept | |
| 586/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MARKED-2342073 |
Yes | Proof of Concept | |
| 586/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MARKED-2342082 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: chalk
The new version differs by 53 commits.- 3fca615 2.0.0
- f66271e Add tagged template literal (#163)
- 23ef1c7 fix linter errors
- c015568 add rainbow example
- 09fb2d8 Re-implement `chalk.enabled` (#160)
- 608242a spoof supports-color
- 18f2e7c add host information output
- 523b998 Revert "TEMPORARY: emergency travis CI fix (see comments)"
- 54975fb TEMPORARY: emergency travis CI fix (see comments)
- 1d73b21 Improve readme
- 6f4d6b3 Bump dependencies
- 8702496 Remove `chalk.styles`
- 0412cdf Minor code improvements
- 249b9ac ES2015ify the codebase
- cb3f230 Add RGB (256/Truecolor) support (#140)
- dbae68d Update dependent package count in the readme (#154)
- 9b60021 Drop support for Node.js 0.10 and 0.12
- 0d21449 check parent builder object for enabled status (#142)
- 5a69476 add XO badge
- 492f11f add example file
- 4ce73b6 make XO happy
- 7c02cf4 Add log statement to chalk examples (#129)
- 835ca3d You've just reached 10,000 dependent modules. (#122)
- 74c087d minor doc improvements (#120)
Package name: front-matter
The new version differs by 123 commits.- 90d23d1 4.0.1
- f71652c Fix case of `allowUnsafe` in boolean coercion
- 80ff5d4 Merge branch 'tyankatsu0105-test/add-declaration-test'
- 2d1bd3f feat: add options args to fm
- 854bab6 chore: remove unused file
- f4d091f test: add typescript description test
- 0ec3a2c 4.0.0
- 5e574da Merge branch 'peterbe-65-yamlsafeload'
- 188b598 Merge branch '65-yamlsafeload' of git://github.com/peterbe/front-matter into peterbe-65-yamlsafeload
- 331fff5 update .travis.yml
- 9658b13 feedbacked
- b87b7d9 and readme
- 7887a05 feedbacked
- 60b3b67 readme update
- 1d9094f yaml.safeLoad()
- eaf33a5 3.2.1
- 7c4156c Merge branch 'mourner-patch-1'
- 0058684 smaller published size
- c50fd45 Update my email
- 9a31548 3.2.0
- 979dc2d Merge branch 'tyankatsu0105-master'
- fb81da2 chore: update declaration
- 3c53424 chore: declaration
- af399ef 3.1.0
Package name: marked
The new version differs by 173 commits.- ae01170 chore(release): 4.0.10 [skip ci]
- fceda57 🗜️ build [skip ci]
- 8f80657 fix(security): fix redos vulnerabilities
- c4a3ccd Merge pull request from GHSA-rrrm-qjm4-v8hf
- d7212a6 chore(deps-dev): Bump jasmine from 4.0.0 to 4.0.1 (#2352)
- 5a84db5 chore(deps-dev): Bump rollup from 2.62.0 to 2.63.0 (#2350)
- 2bc67a5 chore(deps-dev): Bump markdown-it from 12.3.0 to 12.3.2 (#2351)
- 98996b8 chore(deps-dev): Bump @ babel/preset-env from 7.16.5 to 7.16.7 (#2353)
- ebc2c95 chore(deps-dev): Bump highlight.js from 11.3.1 to 11.4.0 (#2354)
- e5171a9 chore(release): 4.0.9 [skip ci]
- 41990a5 🗜️ build [skip ci]
- a9696e2 fix: retain line breaks in tokens properly (#2341)
- 6aacd13 chore(deps-dev): Bump jasmine from 3.10.0 to 4.0.0 (#2343)
- 55e5df9 chore(deps-dev): Bump @ babel/core from 7.16.5 to 7.16.7 (#2344)
- 4f4cab4 chore(deps-dev): Bump eslint-plugin-import from 2.25.3 to 2.25.4 (#2345)
- 97ea9f2 chore(deps-dev): Bump eslint from 8.5.0 to 8.6.0 (#2346)
- 4c3b853 chore(deps-dev): Bump rollup-plugin-license from 2.6.0 to 2.6.1 (#2347)
- 9396896 chore(deps-dev): Bump rollup from 2.61.1 to 2.62.0 (#2338)
- 103a56c chore(deps-dev): Bump @ babel/preset-env from 7.16.4 to 7.16.5 (#2333)
- be771c9 chore(deps-dev): Bump eslint from 8.4.1 to 8.5.0 (#2334)
- 67d5a65 chore(deps-dev): Bump @ babel/core from 7.16.0 to 7.16.5 (#2335)
- 991493a chore(deps-dev): Bump eslint-plugin-promise from 5.2.0 to 6.0.0 (#2336)
- 59375fb chore(release): 4.0.8 [skip ci]
- 4734c82 🗜️ build [skip ci]
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Regular Expression Denial of Service (ReDoS) 🦉 Regular Expression Denial of Service (ReDoS) 🦉 Arbitrary Code Execution 🦉 More lessons are available in Snyk Learn